Impersonation still needs authorization
When an admin or support tool lets someone "act as" another user, that mode is still an authorization decision — not a free pass.
Check all of these before allowing impersonation:
- The actor is allowed to impersonate at all.
- They may assume this specific target (tenant, role, customer tier).
- Which actions are permitted while acting as that user (often a subset of the target's permissions).
- Both identities are recorded on every request and in the audit log.
Impersonation without those checks is privilege escalation dressed as a convenience feature. Authenticate the actor, then authorize the impersonation itself, then authorize each action under the assumed identity.
